vendor:
Encore Web Forum
by:
Schizoprenic
7.5
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: Encore Web Forum
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Unknown
Unknown
Remote Command Execution in Encore Web Forum
The Encore Web Forum is prone to an issue that may allow a remote user to execute arbitrary commands on a system implementing the forum software. This issue is due to the application's failure to properly validate user-supplied URI input. A remote attacker may exploit this condition to execute arbitrary commands in the context of the webserver that is hosting the vulnerable application.
Mitigation:
Implement proper input validation and sanitization to prevent command injection attacks. Update the Encore Web Forum software to the latest version.